Impact
Eclipse hawkBit versions up to 1.0.3 contain a flaw in the Direct Device Integration controller that allows an authenticated device to bypass object‑level authorization checks. A device that holds valid credentials for its tenant can request and download any firmware artifact belonging to the same tenant, even those not assigned to it. This capability enables unauthorized firmware exfiltration and could potentially be leveraged for malicious firmware deployment, though the CVE payload does not explicitly state downgrades or other active attacks.
Affected Systems
The affected product is Eclipse hawkBit from the Eclipse Foundation, specifically versions 1.0.3 and earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authenticated device credentials and occurs within the same tenant, constituting an intra‑tenant privilege escalation that relies on insufficient object‑level authorization controls.
OpenCVE Enrichment